Godfather Android malware now uses virtualization to hijack banking apps

Godfather Android malware now uses virtualization to hijack banking apps

The new version of the β€œGodfather” Android malware uses virtualization to create isolated environments on mobile devices, enabling stealthy theft of banking, cryptocurrency, and e-commerce app data. It employs advanced techniques like StubActivities and API hooking to deceive users and exfiltrate sensitive information, representing a significant evolution in Android threats. #GodfatherMalware #VirtualizationAttack

Keypoints

  • Godfather malware creates virtual environments to hide its malicious activities on Android devices.
  • It targets over 500 banking, cryptocurrency, and e-commerce apps worldwide using virtualization techniques.
  • The malware uses StubActivities and API hooking to intercept and control app behavior without user suspicion.
  • Cybercriminals can steal credentials, capture touch events, manipulate transactions, and exfiltrate data in real time.
  • Protection measures include only downloading apps from trusted sources and enabling Google Play Protect.

Read More: https://www.bleepingcomputer.com/news/security/godfather-android-malware-now-uses-virtualization-to-hijack-banking-apps/